4 * This module handles self-service subscription/unsubscription to mail lists.
6 * Copyright (C) 2002 by Art Cancro and others.
7 * This code is released under the terms of the GNU General Public License.
20 #include <sys/types.h>
22 #if TIME_WITH_SYS_TIME
23 # include <sys/time.h>
27 # include <sys/time.h>
38 #include "sysdep_decls.h"
39 #include "citserver.h"
42 #include "dynloader.h"
49 #include "internet_addressing.h"
50 #include "serv_network.h"
51 #include "clientsocket.h"
60 * Generate a randomizationalisticized token to use for authentication of
61 * a subscribe or unsubscribe request.
63 void listsub_generate_token(char *buf) {
67 /* Theo, please sit down and shut up. This key doesn't have to be
68 * tinfoil-hat secure, it just needs to be reasonably unguessable
71 sprintf(sourcebuf, "%lx",
72 (long) (++seq + getpid() + time(NULL))
75 /* Convert it to base64 so it looks cool */
76 encode_base64(buf, sourcebuf);
81 * Enter a subscription request
83 void do_subscribe(char *room, char *email, char *subtype, char *webpage) {
84 struct quickroom qrbuf;
88 char confirmation_request[SIZ];
95 if (getroom(&qrbuf, room) != 0) {
96 cprintf("%d There is no list called '%s'\n", ERROR, room);
100 if ((qrbuf.QRflags2 & QR2_SELFLIST) == 0) {
102 "does not accept subscribe/unsubscribe requests.\n",
103 ERROR+HIGHER_ACCESS_REQUIRED, qrbuf.QRname);
107 listsub_generate_token(token);
109 assoc_file_name(filename, sizeof filename, &qrbuf, "netconfigs");
112 * Make sure the requested address isn't already subscribed
114 begin_critical_section(S_NETCONFIGS);
115 ncfp = fopen(filename, "r");
117 while (fgets(buf, sizeof buf, ncfp) != NULL) {
118 buf[strlen(buf)-1] = 0;
119 extract(scancmd, buf, 0);
120 extract(scanemail, buf, 1);
121 if ((!strcasecmp(scancmd, "listrecp"))
122 || (!strcasecmp(scancmd, "digestrecp"))) {
123 if (!strcasecmp(scanemail, email)) {
130 end_critical_section(S_NETCONFIGS);
132 if (found_sub != 0) {
133 cprintf("%d '%s' is already subscribed to '%s'.\n",
135 email, qrbuf.QRname);
140 * Now add it to the file
142 begin_critical_section(S_NETCONFIGS);
143 ncfp = fopen(filename, "a");
145 fprintf(ncfp, "subpending|%s|%s|%s|%ld|%s\n",
154 end_critical_section(S_NETCONFIGS);
156 /* Generate and send the confirmation request */
158 urlesc(urlroom, qrbuf.QRname);
160 snprintf(confirmation_request, sizeof confirmation_request,
161 "Content-type: text/html\n\n"
163 "Someone (probably you) has submitted a request to subscribe\n"
164 "<%s> to the <B>%s</B> mailing list.<BR><BR>\n"
165 "<A HREF=\"http://%s?room=%s&token=%s&cmd=confirm\">"
166 "Please click here to confirm this request.</A><BR><BR>\n"
167 "If this request has been submitted in error and you do not\n"
168 "wish to receive the '%s' mailing list, simply do nothing,\n"
169 "and you will not receive any further mailings.\n"
172 email, qrbuf.QRname, webpage, urlroom, token, qrbuf.QRname
175 quickie_message( /* This delivers the message */
179 confirmation_request,
183 cprintf("%d Subscription entered; confirmation request sent\n", CIT_OK);
188 * Enter an unsubscription request
190 void do_unsubscribe(char *room, char *email, char *webpage) {
191 struct quickroom qrbuf;
196 char confirmation_request[SIZ];
202 if (getroom(&qrbuf, room) != 0) {
203 cprintf("%d There is no list called '%s'\n",
204 ERROR+ROOM_NOT_FOUND, room);
208 if ((qrbuf.QRflags2 & QR2_SELFLIST) == 0) {
210 "does not accept subscribe/unsubscribe requests.\n",
211 ERROR+HIGHER_ACCESS_REQUIRED, qrbuf.QRname);
215 listsub_generate_token(token);
217 assoc_file_name(filename, sizeof filename, &qrbuf, "netconfigs");
220 * Make sure there's actually a subscription there to remove
222 begin_critical_section(S_NETCONFIGS);
223 ncfp = fopen(filename, "r");
225 while (fgets(buf, sizeof buf, ncfp) != NULL) {
226 buf[strlen(buf)-1] = 0;
227 extract(scancmd, buf, 0);
228 extract(scanemail, buf, 1);
229 if ((!strcasecmp(scancmd, "listrecp"))
230 || (!strcasecmp(scancmd, "digestrecp"))) {
231 if (!strcasecmp(scanemail, email)) {
238 end_critical_section(S_NETCONFIGS);
240 if (found_sub == 0) {
241 cprintf("%d '%s' is not subscribed to '%s'.\n",
243 email, qrbuf.QRname);
248 * Ok, now enter the unsubscribe-pending entry.
250 begin_critical_section(S_NETCONFIGS);
251 ncfp = fopen(filename, "a");
253 fprintf(ncfp, "unsubpending|%s|%s|%ld|%s\n",
261 end_critical_section(S_NETCONFIGS);
263 /* Generate and send the confirmation request */
265 urlesc(urlroom, qrbuf.QRname);
267 snprintf(confirmation_request, sizeof confirmation_request,
268 "Content-type: text/html\n\n"
270 "Someone (probably you) has submitted a request "
272 "<%s> from the <B>%s</B> mailing list.<BR><BR>\n"
273 "<A HREF=\"http://%s?room=%s&token=%s&cmd=confirm\">"
274 "Please click here to confirm this request.</A><BR><BR>\n"
275 "If this request has been submitted in error and you do\n"
276 "<i>not</i> wish to unsubscribe from the "
277 "'%s' mailing list, simply do nothing,\n"
278 "and you will remain subscribed to the list.\n"
281 email, qrbuf.QRname, webpage, urlroom, token, qrbuf.QRname
284 quickie_message( /* This delivers the message */
288 confirmation_request,
292 cprintf("%d Unubscription noted; confirmation request sent\n", CIT_OK);
297 * Confirm a subscribe/unsubscribe request.
299 void do_confirm(char *room, char *token) {
300 struct quickroom qrbuf;
303 char line_token[SIZ];
311 char address_to_unsubscribe[SIZ];
314 char *holdbuf = NULL;
318 strcpy(address_to_unsubscribe, "");
320 if (getroom(&qrbuf, room) != 0) {
321 cprintf("%d There is no list called '%s'\n",
322 ERROR+ROOM_NOT_FOUND, room);
326 if ((qrbuf.QRflags2 & QR2_SELFLIST) == 0) {
328 "does not accept subscribe/unsubscribe requests.\n",
329 ERROR+HIGHER_ACCESS_REQUIRED, qrbuf.QRname);
333 assoc_file_name(filename, sizeof filename, &qrbuf, "netconfigs");
334 begin_critical_section(S_NETCONFIGS);
335 ncfp = fopen(filename, "r+");
337 while (line_offset = ftell(ncfp),
338 (fgets(buf, sizeof buf, ncfp) != NULL) ) {
339 buf[strlen(buf)-1] = 0;
340 line_length = strlen(buf);
341 extract(cmd, buf, 0);
342 if (!strcasecmp(cmd, "subpending")) {
343 extract(email, buf, 1);
344 extract(subtype, buf, 2);
345 extract(line_token, buf, 3);
346 if (!strcasecmp(token, line_token)) {
347 if (!strcasecmp(subtype, "digest")) {
348 strcpy(buf, "digestrecp|");
351 strcpy(buf, "listrecp|");
355 /* SLEAZY HACK: pad the line out so
356 * it's the same length as the line
359 while (strlen(buf) < line_length) {
362 fseek(ncfp, line_offset, SEEK_SET);
363 fprintf(ncfp, "%s\n", buf);
367 if (!strcasecmp(cmd, "unsubpending")) {
368 extract(line_token, buf, 2);
369 if (!strcasecmp(token, line_token)) {
370 extract(address_to_unsubscribe, buf, 1);
376 end_critical_section(S_NETCONFIGS);
379 * If "address_to_unsubscribe" contains something, then we have to
380 * make another pass at the file, stripping out lines referring to
383 if (strlen(address_to_unsubscribe) > 0) {
384 holdbuf = mallok(SIZ);
385 begin_critical_section(S_NETCONFIGS);
386 ncfp = fopen(filename, "r+");
388 while (line_offset = ftell(ncfp),
389 (fgets(buf, sizeof buf, ncfp) != NULL) ) {
390 buf[strlen(buf)-1]=0;
391 extract(scancmd, buf, 0);
392 extract(scanemail, buf, 1);
393 if ( (!strcasecmp(scancmd, "listrecp"))
394 && (!strcasecmp(scanemail,
395 address_to_unsubscribe)) ) {
398 else if ( (!strcasecmp(scancmd, "digestrecp"))
399 && (!strcasecmp(scanemail,
400 address_to_unsubscribe)) ) {
403 else if ( (!strcasecmp(scancmd, "subpending"))
404 && (!strcasecmp(scanemail,
405 address_to_unsubscribe)) ) {
408 else if ( (!strcasecmp(scancmd, "unsubpending"))
409 && (!strcasecmp(scanemail,
410 address_to_unsubscribe)) ) {
413 else { /* Not relevant, so *keep* it! */
414 linelen = strlen(buf);
415 holdbuf = reallok(holdbuf,
416 (buflen + linelen + 2) );
417 strcpy(&holdbuf[buflen], buf);
419 strcpy(&holdbuf[buflen], "\n");
425 ncfp = fopen(filename, "w");
427 fwrite(holdbuf, buflen+1, 1, ncfp);
430 end_critical_section(S_NETCONFIGS);
435 * Did we do anything useful today?
438 cprintf("%d %d operation(s) confirmed.\n", CIT_OK, success);
441 cprintf("%d Invalid token.\n", ERROR);
449 * process subscribe/unsubscribe requests and confirmations
451 void cmd_subs(char *cmdbuf) {
460 extract(opr, cmdbuf, 0);
461 if (!strcasecmp(opr, "subscribe")) {
462 extract(subtype, cmdbuf, 3);
463 if ( (strcasecmp(subtype, "list"))
464 && (strcasecmp(subtype, "digest")) ) {
465 cprintf("%d Invalid subscription type '%s'\n",
466 ERROR+ILLEGAL_VALUE, subtype);
469 extract(room, cmdbuf, 1);
470 extract(email, cmdbuf, 2);
471 extract(webpage, cmdbuf, 4);
472 do_subscribe(room, email, subtype, webpage);
475 else if (!strcasecmp(opr, "unsubscribe")) {
476 extract(room, cmdbuf, 1);
477 extract(email, cmdbuf, 2);
478 extract(webpage, cmdbuf, 3);
479 do_unsubscribe(room, email, webpage);
481 else if (!strcasecmp(opr, "confirm")) {
482 extract(room, cmdbuf, 1);
483 extract(token, cmdbuf, 2);
484 do_confirm(room, token);
487 cprintf("%d Invalid command\n", ERROR);
495 char *Dynamic_Module_Init(void)
497 CtdlRegisterProtoHook(cmd_subs, "SUBS", "List subscribe/unsubscribe");